Executive brief
Arista VeloCloud Orchestrator (VCO) on-premises contains an input validation flaw that allows remote attackers to bypass security controls and access privileged internal functions. Successful exploitation can compromise the confidentiality, integrity, and availability of the orchestrator and all data it manages, including network configurations and customer data.
Technical details
The vulnerability is an improper input validation flaw in Arista VeloCloud Orchestrator (on-premises deployment). The vulnerability allows a remote attacker without authentication to submit maliciously crafted input that bypasses input validation controls and grants access to privileged internal functionality. The attack requires network access to the VCO host but no prior authentication or user interaction. Successful exploitation enables an attacker to compromise the confidentiality, integrity, and availability of the orchestrator and all data it manages. The vulnerability is known to be actively exploited in the wild.
Affected products
- Arista VeloCloud Orchestrator on-premises deployments
Timeline
- 2026-09-22: disclosed
- exploited